First published: Mon Apr 30 2007(Updated: )
SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WP Links Page | <=1.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-2373 is considered high severity due to its potential for SQL injection attacks that can lead to unauthorized database access.
To fix CVE-2007-2373, upgrade the WF-Links module to a version later than 1.03 that addresses the SQL injection vulnerability.
CVE-2007-2373 affects users of the WF-Links module version 1.03 and earlier on the XOOPS platform.
CVE-2007-2373 can be exploited through SQL injection attacks, allowing attackers to execute arbitrary SQL commands.
You can detect vulnerability to CVE-2007-2373 by testing inputs to the cid parameter in viewcat.php for unexpected SQL query behaviors.